<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OK Google! Bypass the Authentication! in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/OK-Google-Bypass-the-Authentication/m-p/32293#M2214</link>
    <description>&lt;P&gt;W&lt;SPAN&gt;hen a user pronounces the words &lt;EM&gt;“a capo”&lt;/EM&gt; (Italian equivalent of the English “new line”, “new paragraph”) an &lt;U&gt;unspecified Google Assistant App&lt;/U&gt; translates this as the control character \n, interpreting the phrase as if the user had pressed the Enter key, to submit the input.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ok Google! Do you like to process empty input? Yes! So instead of hearing a password for the app, Google Assistant is tricked&amp;nbsp; into falling to the apps "Default Intent" which provides access to the apps main menu.&amp;nbsp;From there, the attacker can access any functionality for any user. Nice! The security researcher that found and responsibly&amp;nbsp;reported&amp;nbsp;it to Google did NOT get any credit or reward&amp;nbsp;&lt;IMG id="smileysad" class="emoticon emoticon-smileysad" src="https://community.isc2.org/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt; although Google did eventually&amp;nbsp;fix it &lt;A href="http://“We are doing our quality control checks, making sure the numbers are accurate." target="_blank" rel="noopener"&gt;here&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;after back tracking from saying it was a "no fix".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:25:28 GMT</pubDate>
    <dc:creator>AppDefects</dc:creator>
    <dc:date>2023-10-09T09:25:28Z</dc:date>
    <item>
      <title>OK Google! Bypass the Authentication!</title>
      <link>https://community.isc2.org/t5/Tech-Talk/OK-Google-Bypass-the-Authentication/m-p/32293#M2214</link>
      <description>&lt;P&gt;W&lt;SPAN&gt;hen a user pronounces the words &lt;EM&gt;“a capo”&lt;/EM&gt; (Italian equivalent of the English “new line”, “new paragraph”) an &lt;U&gt;unspecified Google Assistant App&lt;/U&gt; translates this as the control character \n, interpreting the phrase as if the user had pressed the Enter key, to submit the input.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ok Google! Do you like to process empty input? Yes! So instead of hearing a password for the app, Google Assistant is tricked&amp;nbsp; into falling to the apps "Default Intent" which provides access to the apps main menu.&amp;nbsp;From there, the attacker can access any functionality for any user. Nice! The security researcher that found and responsibly&amp;nbsp;reported&amp;nbsp;it to Google did NOT get any credit or reward&amp;nbsp;&lt;IMG id="smileysad" class="emoticon emoticon-smileysad" src="https://community.isc2.org/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt; although Google did eventually&amp;nbsp;fix it &lt;A href="http://“We are doing our quality control checks, making sure the numbers are accurate." target="_blank" rel="noopener"&gt;here&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;after back tracking from saying it was a "no fix".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:25:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/OK-Google-Bypass-the-Authentication/m-p/32293#M2214</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: OK Google! Bypass the Authentication!</title>
      <link>https://community.isc2.org/t5/Tech-Talk/OK-Google-Bypass-the-Authentication/m-p/32314#M2223</link>
      <description>&lt;P&gt;I'm waiting for the lawsuit when someone's AI drives them off a cliff. In the courtroom the accuser will say:&lt;/P&gt;&lt;P&gt;I said "Alexa, drive me over to Cliff's" and the next thing I know I'm here at the bottom of a cliff.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 14:46:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/OK-Google-Bypass-the-Authentication/m-p/32314#M2223</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2020-02-04T14:46:35Z</dc:date>
    </item>
  </channel>
</rss>

